BSIMM
BSIMM Intelligence (Attack Models, Security Features & Design, Standards & Requirements)

BSIMM SR1.5: Identify open source and manage its risk

Standards & Requirements. Open source components are identified and their risk managed so known-vulnerable or non-compliant components are controlled.

Other controls in BSIMM Intelligence (Attack Models, Security Features & Design, Standards & Requirements)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.